access_token acts as that user (it is the bearer on /buy and the member-token card endpoints) and the refresh_token keeps it alive. Completing the code is the authorization. There is no separate approval screen.
Connection access tokens expire after one hour. Each refresh returns a new refresh token and invalidates the old one.
The connection object
Returned by Verify the code and Refresh the connection.Endpoints
Webhook:
connection.created.